A Drupal Webform vulnerability report usually lands on an executive director’s desk as a forwarded email full of advisory numbers. On September 23, 2026, the Drupal Security Team published 20 of them at once, all for Webform, the module that runs most contact, membership, event and donation forms on Drupal sites. One is rated Critical.
The fix is two version numbers: Webform 6.2.12 or 6.3.1. If your site runs either one or later, you are covered for this release. If you do not know, that is the first thing to find out.
The short version: ask your web vendor or IT lead three questions this week. Are we on Webform 6.2.12 or 6.3.1? Which version of Drupal are we on? And what is the plan for December 9, 2026? That last date is when Drupal 10 reaches end of life, and it matters more to this story than any single advisory.
We covered the technical detail for developers in our Webform security release breakdown. This post is for the person who has to ask the questions, not run the update.
The Drupal Webform vulnerability, in plain terms
Webform is an add-on module for Drupal. It builds the forms your members and donors fill out: join and renew, register for the conference, apply for an award, contact staff.
On September 23, the Drupal Security Team released fixes for 20 security problems in it, listed on its contributed project advisory page. Most are moderate. Most need someone to be logged in, or need a specific form setup. One is Critical.
You may see other counts. Some summaries say 15 or 22. The advisory list shows 20 Webform advisories for that day, and the Webform release notes describe 22 fixes. Either way, the same two updates fix all of them.
What "Critical" actually means
Drupal scores each advisory out of 25. A score of 15 to 19 is Critical. A score of 20 or more is Highly critical. Nothing in this release reached Highly critical.
The Critical one, SA-CONTRIB-2026-175, scores 18. In plain terms, here is what the score says:
- No login needed. A member of the public could trigger it.
- The damage could be serious. Depending on the site, it could expose data or let an attacker run code on the server.
- It needs a specific setup. The form has to use a custom format for questions with multiple answers. Simple contact forms usually do not.
- No known attacks. The advisory rates exploitation as theoretical. It does not report attacks on live sites.
"Critical" here means "patch it now," not "you have been breached." That is the right way to say it to a board.
Which forms the Drupal Webform vulnerability puts at risk
You do not need to read 20 advisories to know where a Drupal Webform vulnerability could hit. Six of them can be reached without logging in, and each depends on a feature many association sites use.
| If your forms do this | Plain-language risk |
|---|---|
| Let people upload files (applications, abstracts, photos) | In some setups, uploaded files could be seen by people who should not see them |
| Send submissions to your AMS or CRM automatically | A tampered reply from the connected system could put harmful script on your pages |
| Appear on partner sites through shared or embedded forms | Spam protection can be bypassed |
| Use custom formats for multi-answer questions | The Critical flaw applies |
The other 14 advisories need someone with a login, usually someone who can build or edit forms. That is where volunteers, temporary staff and former contractors come in. If they still have form-building access, they still have that risk.
What to ask your web vendor about the Drupal Webform vulnerability
Most associations run Drupal through an agency or a part-time developer. Here is a short set of questions you can send as written.
- Which version of Webform are we running? Is it 6.2.12, 6.3.1 or later?
- When was it updated, and did you test our donation, registration and membership forms afterward?
- Do any of our forms use file uploads, send data to our AMS or CRM, or appear on other sites?
- Who has permission to build or edit forms on our site? Can we remove anyone who no longer needs it?
- Which version of Drupal are we on, and what is the plan before Drupal 10 ends on December 9, 2026?
A good vendor answers the first three in one reply. The fifth question is the one that tells you whether they are planning ahead.
If you have admin access yourself, you can check the version under Reports, then Available updates. A screenshot of that page settles the question.
Why Drupal 10’s end of life makes this urgent
This is the part to underline for your board, and the reason a Drupal Webform vulnerability matters more this year. The Webform 6.2 line, the one many Drupal 10 sites use, gets security fixes only until Drupal 10 reaches end of life. The Webform project page says so directly.
Drupal’s release schedule sets that date: December 9, 2026. After it, Drupal 10 gets no more security releases.
Put those together. This month, a Drupal 10 site could fix 20 Webform problems with one update. The next time Webform has a serious flaw after December 9, a Drupal 10 site may have no update to install.
Three facts make this harder to put off:
- The date is fixed. Drupal set it by policy and has not moved it.
- You cannot skip Drupal 11. A Drupal 10 site cannot jump straight to Drupal 12. It has to go to Drupal 11 first.
- Upgrades take time. Moving to Drupal 11 means checking every add-on, including Webform, and testing every form. Our Drupal 10 to 11 upgrade guide covers what is involved.
We explained the deadline in full in what Drupal 10 end of life means for your site. The Webform release is the clearest example yet of why it matters.
What it costs to wait
Waiting on a Drupal Webform vulnerability fix saves little and risks a lot. The update itself is routine for a developer: back up, update, test the forms, deploy.
Waiting on Drupal 10 costs more. An upgrade started in October can be planned, tested and budgeted. An upgrade started in December runs into the holidays, year-end giving and conference registration season, which is when your forms matter most.
There is also no safety net this time. The Drupal Security Team’s network-level protection, Drupal Steward, does not cover this release. The only protection is the update.
A checklist for this week
- Confirm the Webform version is 6.2.12, 6.3.1 or later, so this Drupal Webform vulnerability is closed.
- Test your key forms: donate, join or renew, register, apply and contact.
- Review who can build forms and remove access that is no longer needed.
- Confirm your Drupal version. If it starts with 10, ask for a written Drupal 11 plan with dates.
- Put December 9, 2026 on the board calendar.
This is not the first batch like this. In early September we covered fifteen contributed module advisories on a single day. Expect more of them, and expect them to arrive faster than upgrade projects do.
Frequently Asked Questions
What is the Drupal Webform vulnerability?
It is a set of 20 security advisories for the Webform module, published September 23, 2026. One is rated Critical. All are fixed in Webform 6.2.12 and 6.3.1.
Is my association’s website affected?
If your site runs Drupal and uses Webform below version 6.2.12, or version 6.3.0, it is affected. Ask your vendor which version you run, or check Reports, then Available updates.
Has anyone been attacked through this?
The Critical advisory does not report attacks on live sites and rates exploitation as theoretical. That can change, which is why the update should not wait.
What does “Critical” mean in a Drupal advisory?
It means a risk score of 15 to 19 out of 25. The Critical Webform flaw scores 18: no login needed and serious possible impact, but only on forms with a specific custom setup.
How long does the Webform update take?
For a developer, the update itself is routine. Most of the time goes to testing your forms afterward, especially donation, registration and membership forms.
When does Drupal 10 reach end of life?
December 9, 2026. After that, Drupal 10 gets no more security releases, and the Webform 6.2 line used by many Drupal 10 sites stops getting security fixes too.
Can we wait for Drupal 12 and upgrade once?
No. A Drupal 10 site cannot go straight to Drupal 12. It has to move to Drupal 11 first, and Drupal 10 support ends December 9 either way.
What should I ask my web vendor?
Ask which Webform version you run, when it was updated and tested, which forms use uploads or send data to your AMS or CRM, who can edit forms, and what the Drupal 11 plan is.
Does Drupal Steward protect us?
Not for this release. The Drupal Security Team said these fixes would not be covered by Drupal Steward, so the update is the only protection.